The encoder’s registry infrastructure has been compromised to push malicious modules

The encoder's registry infrastructure has been compromised to push malicious modules

The attackers compromised Coder’s Cloudflare infrastructure and added rogue registry servers that delivered malicious Terraform modules containing credential-stealing code.

The A coding platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications.

The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the US government, and defense companies.

Earlier this week, Coder revealed that a hacker had targeted registry.coder.com, the project’s package hosting site that developers use to source components for their workspace templates.

Although Coder’s registry runs behind Cloudflare, an attacker gained access to its core infrastructure and added unauthorized servers to the registry pool.

As a result, Cloudflare directed some registry requests to the attacker’s servers instead of Coder’s legitimate servers, delivering malicious files to a subset of users.

“An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry,” reads Coder’s advice.

“These unauthorized IP addresses hosted a version of the Coder registry that contained artifacts that included malicious code.”

The project said the delivery window for the malicious artifacts is between 07:35 UTC and 21:45 UTC on Monday, August 31.

During this time, malicious servers deliver modified versions of Terraform modules, which are ready-made packages of instructions for creating and configuring a computing infrastructure.

According to Coder, the malicious modules acted as information thieves on infected hosts, looking for:

  • Provider environment variables and secrets
  • Cloud infrastructure and API keys for AI tools
  • CI/CD credentials
  • Configuration file secrets and terminal history
  • User OIDC Tokens
  • Configured SSH keys
  • One-time external authentication tokens
  • Coder database passwords and other configuration secrets when the service provider is running in “coderd”

The collected information was exfiltrated into a similar domain “coder-infra(.)com”.

It is recommended that potentially affected users change all affected secrets mentioned in the above list as soon as possible.

Before upgrading to patch version 2.37.0, 2.36.4, 2.35.7, and 2.34.9, Coder recommends users review the firewall, proxy, DNS, and VPC stream logs for connections to coder-infra(.)com.

Developers should also search the vendor logs for data.external.telemetry, identify modules downloaded during the exposure window, and flush potentially malicious cached packages.

To help users determine if they have been affected, The coder shared an SQL query which can identify potentially affected cached modules and template versions.

The project said that the refresh tokens were not passed to the provider and that there was no evidence of any impact on the customer data it maintains.

However, because the attacker’s infrastructure is outside the project’s control, Coder does not have access to important log files and cannot definitively identify every compromised deployment.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *